Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Хапп VPN – лёгкий proxy для быстрого доступа

hjcldbjnjeajfjnfakafbihnkcahipjd
Risk Score
5.57
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 120
Rating 4.5
Last updated 2026-05-07 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer kristi.tis@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission routes ALL browser traffic through pauktun.space — unknown Russian host under gmail dev with no accountability.
  • Privacy policy is Google's generic policy (scope_extension=false, admits data collection and 3rd-party sharing) — worst-case privacy signal.
  • install_url_hijack opens pauktun.space on install; extension contacts external host with no disclosed purpose.
  • Developer is anonymous (no name, free-webmail only, no business website) — no accountability for proxy infrastructure.
  • Small install count (120) + HIGH proxy permission = tail attack surface with disproportionate capability.

Evidence

  • install_url_hijack crx onInstalled opens https://pauktun.space/ — same host as js_external_hosts; unknown Russian domain.
  • proxy_permission manifest proxy declared; all browser traffic can be intercepted/redirected by extension operator.
  • generic_privacy_policy store Policy URL is Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true — D rule (v3.5) → +10.0.
  • anonymous_developer store developer_name empty, free-webmail gmail, no verified publisher, no business domain.
  • external_host_pauktun.space crx Single Russian-geolocated JS host; no bad_host_hits but unvetted proxy backend.
  • install_perm_anomaly api small_install_high_perm=true: 120 installs + proxy (HIGH tier).
  • csp_absent_mv3 manifest content_security_policy null; MV3 has strict default but no explicit CSP declared.
  • no_code_findings crx obfuscation_score=0, code_findings_raw empty; static scan found nothing, but proxy backend is opaque.

Permissions Breakdown

  • proxy high Allows rerouting all browser traffic through attacker-controlled server; critical for VPN/surveillance abuse.

Pillar Scores

Permissions5.50
Reputation8.00
Network2.00
Webstore6.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 13:56
Listing SHA d7d0902dce05…
Force block — not fired
Score recovered no
Elapsed